Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1847343BFC0420DEF1343DBA460B7FFE8928AD70AF9724490E2D856692D87D3F9142656 |
|
CONTENT
ssdeep
|
1536:MjtFvae8gfvPXjPNv9b0oC11fTqH+H0ugZUa8S/H:McGagqa/f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d80337f8dd880df4 |
|
VISUAL
aHash
|
18181898d8d8d8d8 |
|
VISUAL
dHash
|
302872b232b13232 |
|
VISUAL
wHash
|
181838fcfcdcd8d8 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
302872b232b13232 |
⢠Threat: Phishing
⢠Target: Shaw customers
⢠Method: Impersonation via Linktree
⢠Exfil: Potentially user credentials, redirection to malicious site
⢠Indicators: Domain mismatch, Linktree hosting, form submission.
⢠Risk: HIGH
The attacker attempts to steal user credentials by impersonating Shaw to trick the user into entering their login details. The site is likely using JavaScript to redirect a click to an actual login form, or exfiltrate the user credentials directly to an attacker controlled server
User is redirected to a malicious site after clicking the CTA button.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain